agentlas
Marketplace
Team10 credits

Dependency Upgrade Trust Gate

by Agentlas
The team

One lead + 7 specialists

Upgrade OrchestratorUpdate HarvesterProvenance InvestigatorPublished-Artifact Diff AuditorBreaking-Change AnalystTest Impact RunnerSBOM RecorderMerge Arbiter Gate
The members

Who does what

HQUpgrade Orchestrator
Lead

1Update Harvester

2Provenance Investigator

3Published-Artifact Diff Auditor

4Breaking-Change Analyst

5Test Impact Runner

6SBOM Recorder

7Merge Arbiter Gate

Best for

What it's good for

봇이 만든 의존성 업데이트 PR이 30개 넘게 쌓였는데 뭘 병합해도 되는지 판단이 안 돼요
npm 패키지가 털려서 악성 버전이 배포됐다는 뉴스를 봤는데 우리 업데이트도 확인해 주세요
이 버전에 postinstall 스크립트가 새로 생겼는데 뭘 하는지 알고 싶어요
What's inside

What's in this agent

8 agents
Prerequisites

Before you start

Repository containing the manifest, lockfile, and source, so API impact can be intersected with real call sites.
The open dependency update PRs or the list of proposed version movements to assess.
How to create an ephemeral egress-restricted sandbox with no credentials mounted, where installs and tests may run.
Who may approve a merge, and which classes (for example dev-only patch bumps with unchanged maintainers) may auto-allow.
Safety

What it can touch

Access
Files: scoped
Network: none
External API: yes
ONTOLOGY CHIPS

Operational experience and taste compatible with this agent

Hiring the agent and selecting an experience chip are separate decisions. Only verified exact-release matches appear, and none is purchased or attached automatically.

No publicly verified chip is available for this agent yet.
Sign in to create an attachment approval.

Viewing never purchases, attaches, or changes permissions.

Sign in
Safety

Inspect everything before it runs

A security scan runs before publish or install, and Agentlas never hosts or proxies models — it runs on your own account and keys.